HimalayasHimalayas logo
Upwind SecurityUS

GRC Senior Analyst

Upwind Security is revolutionizing cloud security by providing a unified platform that empowers organizations to manage their cloud security posture effectively while minimizing alert fatigue.

Upwind Security
India only

Stay safe on Himalayas

Never send money to companies. Jobs on Himalayas will never require payment from applicants.

Description

Upwind is a next-generation Cloud Security Platform that leverages runtime context to identify and prioritize critical risks, providing precise insights and efficient cloud security management. Unlike traditional tools, Upwind uses runtime data proactively for risk prioritization and posture insights, ensuring teams focus on what truly matters. With industry-leading efficiency and eBPF-powered sensors, Upwind delivers comprehensive capabilities, including agentless cloud posture discovery, real-time threat protection, and integrated API security. From misconfigurations to malware defense, Upwind ensures end-to-end, cost-effective cloud infrastructure protection. At Upwind, you’ll have the opportunity to think creatively, explore new ideas, and use your skills to make a meaningful impact on our growth.

Upwind Security is seeking a highly motivated GRC (Governance, Risk, and Compliance) Analyst to join our growing Security & Compliance team. In this role, you will be responsible for supporting the implementation, operation, and continuous improvement of our GRC framework. You will help ensure our organization’s policies, procedures, and controls align with regulatory requirements and industry best practices.

Responsibilities

  • Support the execution and enhancement of the organization’s GRC strategy, including policy governance, risk assessments, compliance monitoring, and audit support.
  • Assist in maintaining compliance with security frameworks and standards such as ISO 27001, SOC 2, NIST, and GDPR.
  • Conduct periodic risk assessments and control gap analyses across departments.
  • Track remediation of audit findings, risks, and control deficiencies, and validate completion of corrective actions.
  • Support third-party risk management activities including vendor due diligence and ongoing assessments.
  • Help maintain the GRC tool and ensure timely updates of risk registers, controls, and evidence repositories.
  • Collaborate cross-functionally with IT, Legal, Engineering, and other business units to promote a culture of security and compliance.
  • Assist in the creation and maintenance of documentation such as policies, standards, and procedures.
  • Prepare reports and dashboards for management review.
  • Stay updated on emerging regulations, standards, and security trends.

Requirements

  • Bachelor’s degree in Information Security, Risk Management, Computer Science, or a related field.
  • 4-6 years of experience in GRC, cybersecurity, risk management, or a compliance-focused role.
  • Familiarity with common regulatory and compliance frameworks (e.g., ISO 27001, SOC 2, HIPAA, PCI-DSS, NIST CSF).
  • Experience working with GRC platforms such as Vanta, Drata, OneTrust, or similar tools is a plus.
  • Excellent communication, documentation, and stakeholder engagement skills.
  • Strong attention to detail and organizational skills.
  • Relevant certifications (e.g., CISA, CISM, CRISC, ISO 27001 LA, or similar) are a plus.

About the job

Apply before

Posted on

Job type

Full Time

Experience level

Education

Bachelor degree

Experience

4 years minimum

Location requirements

Hiring timezones

India +/- 0 hours

About Upwind Security

Learn more about Upwind Security and their company culture.

View company profile

Upwind Security is on a mission to empower our customers to run cloud environments securely and efficiently, accelerating their businesses and focusing on what’s next. Founded by the team behind Spot.io, which was acquired by NetApp, Upwind brings unmatched expertise in cloud infrastructure to the forefront of cybersecurity. The platform consolidates cloud security into a comprehensive and intuitive user experience, drastically reducing alert fatigue and providing relevant, actionable insights in real-time.

Upwind is redefining cloud infrastructure security with its innovative approach. It unifies various security capabilities to deliver seamless integration between Dev, Sec, and Ops teams. By providing powerful context about applications and infrastructure behavior, Upwind enables security professionals to quickly navigate complex security challenges and focus on the most critical vulnerabilities. Companies leveraging the Upwind platform have reported significant improvements in their security workflows and collaboration efforts, allowing them to prioritize effectively and reduce operational noise, making it a game-changer in the cloud security landscape.

Claim this profileUpwind Security logoUS

Upwind Security

Chief executive officer

Amiram Shachar

View company profile

Similar remote jobs

Here are other jobs you might want to apply for.

View all remote jobs

23 remote jobs at Upwind Security

Explore the variety of open remote roles at Upwind Security, offering flexible work options across multiple disciplines and skill levels.

View all jobs at Upwind Security

Remote companies like Upwind Security

Find your next opportunity by exploring profiles of companies that are similar to Upwind Security. Compare culture, benefits, and job openings on Himalayas.

View all companies

Find your dream job

Sign up now and join over 100,000 remote workers who receive personalized job alerts, curated job matches, and more for free!

Sign up
Himalayas profile for an example user named Frankie Sullivan